nd2no Posted December 15, 2009 Report Share Posted December 15, 2009 HI AllI am running 6 DC in windows 2003 evnironment. Lately I have begun to audit event ID 675 for bad passwords. My query here is that when a user enters a bad password while logging it it generates the event ID 675 with service name krbtgt\domain. 4 of these will lock out accounts. What gets me is I am noticing that there are further entries for Event ID 675 from all thru the nite (i.e when a user is out of office) where the service name is krbtgt\domain.net.local. Does anyknow why there is a difference in service name and why this events are being created???regards Quote Link to comment Share on other sites More sharing options...
MANEMAN Posted December 15, 2009 Report Share Posted December 15, 2009 From the information you have given I would put my money on Malware. (Trojan/Virus)Something or someone trying to log in in the middle of the night ? Highly suspicious.Any disgruntled ex-employees left the workplace in the recent past who may have dropped something nasty in the works ?Do a close down, scan it, update it, defrag it, and generally clean it up. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.